Comprehensive data privacy, biometric processing, and security charter detailing how Binfrex collects, safeguards, encrypts, processes, transfers, and retains user personal, telemetry, and transactional information.
Binforex Solution Lab (operating internationally under the official commercial trade brand "Binfrex"), having its registered corporate headquarters at 10 Marina Blvd, Marina Bay Financial Centre, Singapore 018983 (the "Company", "Data Controller", "We", "Us", "Our"), is dedicated to upholding the highest global benchmarks of privacy preservation, cryptographic confidentiality, and regulatory data protection for every individual who accesses or registers on our digital options trading terminal, P2P marketplace, copy trading network, affiliate dashboard, API endpoints, or mobile interfaces (the "Client", "User", "Trader", "Data Subject").
By creating an account, undergoing KYC identity verification, depositing funds, or executing digital option trades on Binfrex, you explicitly and unequivocally consent to the collection, cryptographic encryption, international routing, and regulatory processing of your Personal Data in accordance with this Policy.
2.1. Personal Data: Any information relating to an identified or identifiable natural person who can be identified, directly or indirectly, by reference to an identifier such as legal name, national identification number, biometric vector, location telemetry, or online device fingerprint.
2.2. Processing: Any operation performed upon Personal Data, whether automated or manual, including collection, recording, structuring, cryptographic storage, alteration, retrieval, consultation, transmission, or irreversible erasure.
2.3. Biometric KYC Data: 3D facial geometry coordinate vectors, liveness detection video frames, and anti-spoofing telemetry captured strictly for statutory identity verification and synthetic deepfake fraud prevention.
2.4. Telemetry & Financial Logs: Millisecond-level trade order timestamps, strike prices, asset symbols, public IP addresses, hardware fingerprints, blockchain transaction hashes (TXIDs), and P2P escrow transaction journals.
To provide secure trading terminal access, process multi-chain cryptocurrency deposits, maintain statutory AML/KYC compliance, ensure Local-to-Local P2P escrow integrity, and deliver real-time quote feeds, the Company collects and categorizes the following data sets:
3.2. Special Category Data: The Company does not collect genetic, health, philosophical, religious, or political data. Biometric facial templates are processed strictly under GDPR Article 9(2)(a) and Section 9 of the Singapore PDPA for secure identity verification and fraud prevention with explicit user consent.
Binfrex gathers information through four primary operational vectors:
4.1. Direct Client Submission
Data provided explicitly during account registration, KYC profile completion, payment method creation (e.g. adding local bank details or crypto withdrawal addresses), submitting support tickets, or interacting with P2P counterparty chat boxes.
4.2. Automated Trading Engine & WebSocket Telemetry
Whenever you connect to the web terminal or mobile app, our high-frequency matching engine records tick-level interaction data, contract execution timestamps, price quote sync latencies, chart indicator configurations, and network transport headers.
4.3. Affiliate & S2S Server Postback Tracking
When navigating via partner links, our attribution engine logs referral tokens, click IDs, promo code associations, and Server-to-Server (S2S) postback parameters (such as {click_id} and {sumdep}) strictly for partner tier calculation.
4.4. Third-Party KYC & Blockchain Intelligence
We obtain identity verification scores, PEP screening results, sanctions list matches, and blockchain wallet risk metrics from authorized identity verification vendors and on-chain AML analytics providers.
The Company processes Personal Data strictly in accordance with recognized statutory legal bases under GDPR Article 6, the Singapore Personal Data Protection Act 2012, and international financial regulations:
1. Performance of Contract (GDPR Art. 6(1)(b) & PDPA Sec. 13)
To create and service your account, process digital option orders (Turbo 5s–5m and Classic), calculate expiration payouts, lock and release P2P Escrow smart-vaults, execute crypto deposits and withdrawals, and deliver tournament prizes.
2. Legal & Statutory Compliance (GDPR Art. 6(1)(c) & FATF)
To comply with international Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF), FATF Recommendation 16 (Travel Rule), sanctions compliance screening (OFAC, UN, EU, MAS), and statutory financial tax reporting mandates.
3. Legitimate Interests (GDPR Art. 6(1)(f))
To detect and prevent multi-account fraudulent abuse, self-referral affiliate manipulation, price feed latency exploitation, automated bot intrusion, cyber attacks, and to maintain 99.9% terminal availability.
4. Explicit & Informed Consent (GDPR Art. 6(1)(a) & Art. 9(2)(a))
For processing 3D facial biometric liveness checks during KYC, delivering non-essential marketing updates, enabling optional Telegram bot alerts, and customizing platform interface preferences. Consent can be revoked at any time.
6.1. Local-to-Local P2P Counterparty Data Visibility
Our P2P Escrow marketplace operates on a strictly Local-to-Local domestic payment base across all supported countries (e.g., UPI, Pix, Bkash, Nagad, SEPA, local bank wire). To facilitate direct fiat transfers between matched peers with 0% platform fee, only the following strictly necessary information is displayed to your counterparty during an active trade:
Note: Your complete KYC documentation, passport scans, residential address, total net worth, and crypto wallet balances remain completely confidential and are NEVER disclosed to any P2P counterparty.
6.2. Copy Trading & Tournament Public Profiles
6.3. P2P Dispute Chat Logs Retention
Encrypted chat transcripts and payment receipt uploads generated during P2P orders are preserved in secure escrow archives for 180 days solely for dispute investigation, chargeback resolution, and anti-fraud arbitrations.
The Company never sells, rents, or monetizes Client data. Personal Data is shared strictly with audited technical sub-processors under binding Data Processing Agreements (DPAs):
Identity & Compliance:
Certified KYC vendors executing automated 3D facial matching, sanctions scanning, and on-chain blockchain risk analytics.
Cloud & Infrastructure:
Enterprise Tier-4 data centers, DDoS protection shields, TLS termination nodes, and redundant encrypted database clusters.
International Transfers: All cross-border data routing outside Singapore or the European Economic Area (EEA) is governed by EU Standard Contractual Clauses (SCCs), Singapore PDPA transfer adequacy certifications, and end-to-end cryptographic encapsulation.
Cryptographic Safeguards:
Operational Defenses:
Binfrex adheres strictly to statutory data minimization principles. Personal Data is retained only for the timeframe necessary to accomplish its intended processing objective or satisfy applicable financial audit laws:
9.1. AUTOMATED 3-MONTH (90 DAYS) INACTIVITY ACCOUNT & DATA DELETION
In accordance with our strict platform hygiene and data minimization framework, if an account experiences 3 consecutive months (90 calendar days) of total dormancy and inactivity (defined as zero successful logins, zero trading executions, and zero deposit/withdrawal transactions):
9.2. Statutory Data Retention Schedule Matrix
| Data Classification | Retention Horizon | Statutory / Legal Basis |
|---|---|---|
| Active Trading Profile | Duration of active relationship | Performance of Contract (GDPR Art. 6(1)(b)) |
| Dormant / Inactive Account | Auto-deleted after 3 Months (90 Days) | Data Minimization (GDPR Art. 5(1)(e)) |
| Verified KYC Documents & Biometrics | 7 Years following account closure | Global AML/CTF & FATF Directives |
| Financial Ledger & Trade Journals | 7 Years following trade settlement | Corporate Tax & Financial Audit Law |
| P2P Escrow Dispute Transcripts | 180 Days post-order completion | Dispute Resolution & Fraud Arbitrations |
| Server Logs & Telemetry Data | 12 Months rolling lifecycle | Cybersecurity & Threat Monitoring |
Under applicable data protection frameworks, you have the following enforceable rights:
We use strictly essential session tokens, security CSRF headers, and localized preference cookies:
dpo@binfrex.com
SLA: 30 Calendar Days for DSAR inquiries
support@binfrex.com
Account Security & Verification Desk
Binforex Solution Lab • 10 Marina Blvd, Marina Bay Financial Centre, Singapore 018983
Binfrex Global Data Governance • Active Enforcement v1.0
SEAL: SHA256-PRIV2026-GDPR-PDPA-ENFORCED-BINX
Related Platform Charters & Legal Annexes